forensic-extract-indicators
Extract indicators of compromise from passing rows.
This command is only meaningful while an import is running - imports append it to their own load queries, so you will not write it yourself.
forensic-extract-indicators image=VALUE file=VALUE
- image=VALUE
- Required. Forensic image GUID
- file=VALUE
- Required. Evidence file name